Generating certification authority authenticated public keys in ad hoc networks

被引:4
作者
Kounga, G. [2 ]
Mitchell, C. J. [3 ]
Walter, T. [1 ]
机构
[1] DOCOMO Commun Labs Europe GmbH, D-80687 Munich, Germany
[2] Hewlett Packard Labs, Cloud & Secur Lab, Bristol BS34 8QZ, Avon, England
[3] Univ London, Informat Secur Grp, Egham TW20 0EX, Surrey, England
关键词
public key cryptosystems; authentication; security; hash chains; ENCRYPTION;
D O I
10.1002/sec.279
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In an ad hoc network, nodes may face the need to generate new public keys. To be verifiably authentic, these newly generated public keys need to be certified. However, because of the absence of a permanent communication infrastructure, a certification authority (CA) that can issue certificates may not always be reachable. The downside is that secure communication channels cannot be established. Previously proposed solutions do not guarantee that identities contained in certificates are valid or, when they do, they rely on neighbors to validate user-key bindings. However, there is no guarantee that nodes that are known in advance will always be present in the network. Therefore, neighbors are not always able to verify a node's identity before certificate issuance. In this paper we define a scheme that permits nodes to generate, on-demand, and independently of any third entity, public keys that can be authenticated with the aid of a unique certificate, issued by a CA at initialization. This certificate binds a valid identity to a hash code. We then extend this scheme to a solution permitting certificates to be generated, on-demand, and independently of any third entity, that can be authenticated with a unique signature generated by a CA. Finally we solve the problem of updated revocation information. Copyright (C) 2010 John Wiley & Sons, Ltd.
引用
收藏
页码:87 / 106
页数:20
相关论文
共 34 条
[1]  
[Anonymous], 2002, SCS COMM NETW DISTR
[2]  
[Anonymous], 2005, Proceedings of the 3rd ACM Workshop on Security of Ad Hoc and Sensor Networks, SASN'05
[3]  
[Anonymous], 2003, RSA Laboratories Cryptobytes
[4]  
[Anonymous], 2002, RSA CryptoBytes
[5]  
Bohio M., 2004, Proceedings. Second Annual Conference on Communication Networks and Services Research, P69, DOI 10.1109/DNSR.2004.1344713
[6]   Identity-based encryption from the Weil pairing [J].
Boneh, D ;
Franklin, M .
SIAM JOURNAL ON COMPUTING, 2003, 32 (03) :586-615
[7]   Self-organized public-key management for mobile ad hoc networks [J].
Capkun, S ;
Buttyán, L ;
Hubaux, JP .
IEEE TRANSACTIONS ON MOBILE COMPUTING, 2003, 2 (01) :52-64
[8]  
Deng HM, 2004, ITCC 2004: INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: CODING AND COMPUTING, VOL 1, PROCEEDINGS, P107
[9]  
DESMEDT Y, 1990, CRYPTO 89, P307
[10]  
DESMEDT YG, 1994, EUR T TELECOMMUN, V5, P449